CVE-2007-6211

Debian GNU/Linux - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-6211. PoCs published by bannedit.

AI-analyzed exploit summary This exploit leverages a file append vulnerability in the 'sing' utility to create a malicious logrotate configuration file. The configuration executes arbitrary commands as root when logrotate processes it, leading to privilege escalation.

Description

Send ICMP Nasty Garbage (sing) on Debian GNU/Linux allows local users to append to arbitrary files and gain privileges via the -L (output log file) option. NOTE: this issue is only a vulnerability in limited environments, since sing is not installed setuid, and the administrator would need to override a non-setuid default during installation.

Exploits (1)

exploitdb WORKING POC VERIFIED
by bannedit · clocallinux
https://www.exploit-db.com/exploits/4698

This exploit leverages a file append vulnerability in the 'sing' utility to create a malicious logrotate configuration file. The configuration executes arbitrary commands as root when logrotate processes it, leading to privilege escalation.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: sing (version not specified)
No auth needed
Prerequisites: Presence of the 'sing' utility · Write access to /etc/logrotate.d/ · logrotate service running
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/44157
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/484591/100/200/threaded
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/484472/100/0/threaded
Exploit third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/3412
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/26679
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/38822

Scores

EPSS 0.0089
EPSS Percentile 54.6%

Details

CWE
CWE-264
Status published
Products (1)
sing/sing 1.1
Published Dec 04, 2007
Tracked Since Feb 18, 2026